b074dcb5-b278-4434-bdd9-14a055d724f3
mlgbbiicaihflrnh.sys
Description
Confirmed vulnerable driver from Microsoft Block List
This download link contains the malicious driver!
Use Case | Privileges | Operating System |
---|---|---|
Elevate privileges | kernel | Windows |
Detections
YARA 🏹
Resources
CVE
Known Vulnerable Samples
Property | Value |
---|---|
Filename | |
Creation Timestamp | 2016-09-05 00:43:33 |
MD5 | 5fec28e8f4f76e5ede24beb32a32b9d7 |
SHA1 | fcf9978cf1af2e9b1e2eaf509513664dfcc1847b |
SHA256 | 7433f14b40c674c5e87b6210c330d5bcaf2f6f52d632ae29e9b7cf3ca405665b |
Authentihash MD5 | 37458813b5115cbf06552da28fefbbbb |
Authentihash SHA1 | 1d1cafc73c97c6bcd2331f8777d90fdca57125a3 |
Authentihash SHA256 | faa08cb609a5b7be6bfdb61f1e4a5e8adf2f5a1d2492f262483df7326934f5d4 |
RichPEHeaderHash MD5 | b2f23c03be4553a744ff25735a80073c |
RichPEHeaderHash SHA1 | 2703d60c8f12df9d6adf5ae475bfeb1786486888 |
RichPEHeaderHash SHA256 | 46ffd109664b6694974986a39d508002d564434d60a0fb9f861401f2cb2c83f1 |
Imports
Expand
- ntoskrnl.exe
Imported Functions
Expand
- IoDeleteSymbolicLink
- RtlInitUnicodeString
- IofCompleteRequest
- MmGetSystemRoutineAddress
- IoCreateSymbolicLink
- IoCreateDevice
- IoDeleteDevice
Exported Functions
Expand
Sections
Expand
- .text
- .data
- .pdata
- .info
- INIT
Signature
Expand
last_updated: 2024-09-26